Tuesday, August 7, 2012

Fraud attempts in social networks – This is how scam on Facebook works

Fraud attempts in social networks
This is how scam on Facebook works

As of May 2012, the world’s largest social network Facebook can boast more than 842 million users – an impressive number considering there are 7 billion people on the planet. The more people connected on a centralized platform, the more interesting it becomes for Internet criminals, to everyone's dismay
Every year, there is more news about fraud attempts, identity theft, and hacker attacks on Facebook. It is no wonder, as these actions occur in real-time, and exciting news are spread at the speed of light thanks to activities in this network. Most attacks are based on scam, i.e. fraud that no anti-virus or anti-malware software is able to protect you from, as it is not always malicious software that is used. The authors rather rely on their victims' naivety or greed. This is reason enough for us to explain the general proceedings, so you can avoid scam more efficiently and use Facebook in a more secure manner in the future.

This is how the fraudsters proceed

The criminals' goal is to arouse as many people's interest as possible to have as many potential victims as possible. This is mostly based on spectacular news. It is often a world-famous person; for example, they used Whitney Houston's or Steve Jobs's death for their financial goals. In both cases, there was apparently red hot news about one of the celebrities, such as a video showing the diva shortly before her tragic death. But also less spectacular news are used to raise your interest.
Once the fraudster has managed to raise tthe victim's interest, he is already halfway there. It is traditionally about clicking on an external link or liking a Facebook app that will take you to the spectacular content. One can very clearly see what this fraud is about of course, this piece of news is just fake. It is a psychological trick, as when faced with sensational news, we tend to ignore the voice of reason and act just like the scammers want us to.
The fraudster now has several options. Sometimes links to YouTube videos or websites are created in order to increase the number of clicks. Other common ways are forcing you to take surveys, which the fraudster gets money for, or phishing attempts and spreading malware. As this is a considerable risk to your private data and your wallet, you should be careful and not fall for the scammers' methods.

Facebook Scam in real life

Enough on the theory, let us have a look at real scam campaigns.
Example 1: Amy Winehouse
Amy Winehouse was found dead in her apartment in July 2011. Thanks to active public interest, the first scam attempts did not take long to appear. The most successful one promised a shocking video showing the deceased singer shortly before her death.
There was of course no such video. In reality, you were directed to the following page:
You were then asked to first spread the link in order to reach as many Facebook users as possible. Not only that, but there was also a survey to take in order to win an iPad 2. That is when the victim started wondering why nothing else happened and saw merely a trivial video or none at all. The hacker achieved what he was out for: The alluring message has been spread, and he had earned money with the survey taken.
Example 2: Steve Jobs
The Apple founder's death was also abused by online fraudsters. Within no time several Facebook pages were created, partially supposedly by Apple, partially simply by "a company". The content, however, was always the same:
A considerable amount of iPads was to be raffled off in memory of the recently deceased. This amount varied between 50 and 500 pieces. The scammers' intentions were different as well; apart from asking the victims to take surveys, some versions redirected them the victims to online casino websites. This example clearly shows how many people fell for such tricks and spread the message.
Example 3: Fake apps
The authors of fake apps followed a slightly different path from the aforementioned ones.
This is an application that pretends to show how many people visit your profile. The message is traditionally spread over your friends' walls.
Once your interest has been aroused, the application requests permission to acces all your Facebook data and functions. This ensures the fake app spreading further. The collected data can be used to send spam or is sold off to commercial mail senders.
The aforementioned surveys are used as well – an easy way of earning for the scammer. Such scam apps are of course deleted by Facebook as soon as they find out about them. The authors, however, never stop, though, creating new applications with alternating names.
Example 4: Fake friend requests
The aforementioned fraud attempts relied on Facebook as a means of communication. The fraudsters also send fake e-mails supposedly sent by Facebook such as the following friend request.
The link will not take you to Facebook, but to a fake copy of the site. This site pretends you need to update Macromedia Flash.
Clicking on the link and launching updateflash.exe is fatal: It is the well-known trojan called Zeus or Zbot. As if this were not enough already, there is an exploit kit on the website if the victim does not launch the fake update.
This will put your personal data and the security of your PC at high rish!

How to protect yourself

All scam attempts would have no success if the recipients did not fall for the alluring message. Please keep the following points in mind:
  • Be skeptical!
    Exciting news is not only spread over Facebook, but also over regular websites as well as radio and TV stations. If there is no news about this topic, it is very likely to be scam. Question raffles – why would anyone give away iPads in honor of Steve Jobs, and what's more, why would they do so on Facebook?
    Hint: Google corresponding keywords such as "Amy Winehouse Video". This will often give you hints about fraud attempts.
  • Be vigilant on who sends you mails and how they address you.
    When receiving friend requests or other e-mails, please check the language. If you are using Facebook in English, Facebook sends you messages in English. Plus, you will be addressed with the name you are registered with.
  • Check links!
    Do links contained really take you to the original company website? You can see where the link takes to by hovering over the link with the cursor. If the URL looks cryptic: Hands off!
  • Do not trust your Facebook friends blindly!
    Spreading of scam is usually based on pyramid schemes. Break the chain by not buying into messages and status messages of your Facebook friends.
  • Use anti-virus software with real-time protection!
    Even if you have fallen for a scam attempt, it does not necessarily mean your PC has been infected with malicious software. Emsisoft Anti-Malware offers, for instance, triple protection by blocking malware through its powerful dual-engine scanner or behavior analysis before it is launched. In addition, surf protection warns you about many phishing websites when trying to access them.

Have a nice (malware-free) day!
(864) 498-0569

Thursday, June 7, 2012

Facebook Privacy Notice Chain Letter Is A Hoax

Facebook privacy notice chain letter is a hoax: Facebook users have been spreading a chain letter recommending that their friends post a notice to their walls prohibiting Facebook and the US government from using their content. It is a chain letter/hoax and has no legal merits.


Facebook logoSorry folks, but posting a supposed legal disclaimer to your Facebook profile does not alter the Terms of Service (ToS) or privacy policies governing how your content is viewed on Facebook.
Many (dozens!) of Facebook users have submitted tips to Naked Security over the last week alerting us to a new chain letter/hoax circulating among well-meaning Facebook users.
The message reads as follows:

"Facebook is now a publicly traded entity. Unless you state otherwise, anyone can infringe on your right to privacy once you post to this site. It is recommended that you and other members post a similar notice as this, or you may copy and paste this version. If you do not post such a statement once, then you are indirectly a......llowing public use of items such as your photos and the information contained in your status updates.
PRIVACY NOTICE: Warning - any person and/or institution and/or Agent and/or Agency of any governmental structure including but not limited to the United States Federal Government also using or monitoring/using this website or any of its associated websites, you do NOT have my permission to utilize any of my profile information nor any of the content contained herein including, but not limited to my photos, and/or the comments made about my photos or any other "picture" art posted on my profile.
You are hereby notified that you are strictly prohibited from disclosing, copying, distributing, disseminating, or taking any other action against me with regard to this profile and the contents herein. The foregoing prohibitions also apply to your employee , agent , student or any personnel under your direction or control.

The contents of this profile are private and legally privileged and confidential information, and the violation of my personal privacy is punishable by law. UCC 1-103 1-308 ALL RIGHTS RESERVED WITHOUT PREJUDICE. (M)"
Terms and Conditions image courtesy of ShutterstockUnfortunately taking control of your online identity is not as simple as making a declaration on your Facebook wall. Using any website to store content or personal details requires compliance with the site'sTerms of Service.
These messages are simply another chain letter type hoax pinned upon wishful thinking.
If you are uncomfortable with Facebook monetizing your content or making your content available to the US government you either need to avoid posting the content to Facebook, or more carefully control your privacy settings and hope the authorities don't seek a court order for your information.
If you receive one of these messages from a friend, kindly notify them that it is not legally valid. You might also suggest they check with Snopes or theNaked Security Facebook page before propagating myths.
(864) 498-0569

Wednesday, March 21, 2012

Hand over your Facebook username and password if you want a job

Hand over your Facebook username and password if you want a job: What would you do at a job interview if the interviewer requested your Facebook username and password?


Job interview - cartoon by CarolePicture it: you are at a job interview, and the interviewer requests that you log into your Facebook account so they can shoulder surf as you lay bare your profile in its entirety.
Worse, what if they ask you to hand over your Facebook username and password?
You might laugh and say I would never do that, but what if you really, really need a job? Many of us are desperate for work at the moment, so it is no surprise that some feel they must comply to avoid being stricken from the candidates' list.
In the US, this tactic has been used with people applying for police officer or 911 dispatcher roles, according to an AP article. But the report says that it is happening elsewhere too.
The reason that an increasing number of employers want full access to a Facebook account is perhaps due to more of us hiding information from people we aren't connected with.
Rob MacLeod was shortlisted for a police job in Baltimore when he was asked for his Facebook password. The Spec reports that:
The question startled MacLeod, now a bylaw enforcement officer in Peel Region. He had a personal policy of not sharing his password, no matter the circumstances. So when the request came, MacLeod offered to log in to his Facebook account and then leave the room so the interviewer could browse his page.

But he says the interviewer remained firm — he wanted the password. After a few minutes, MacLeod gave it to him.

MacLeod says he "felt like I was being pressured into doing it. It felt like if I didn’t do it, he would call the recruiter and say, 'This guy’s not interested in the job'", he told The Spec.
It is not surprising that this interview technique is riling a number of individuals and groups, including American Civil Liberties Union (ACLU) attorney Catherine Crump, who states:
It’s an invasion of privacy for private employers to insist on looking at people’s private Facebook pages as a condition of employment or consideration in an application process. People are entitled to their private lives. You’d be appalled if your employer insisted on opening up your postal mail to see if there was anything of interest inside. It’s equally out of bounds for an employer to go on a fishing expedition through a person’s private social media account.
And Orin Kerr, Professor of Law at George Washington University, told AP “It’s akin to requiring someone’s house keys... [It’s] an egregious privacy violation.”
One can understand that companies want to do everything they can to ensure that candidates will be a good fit and won't jeopardize the company, but asking for the keys to their personal Facebook account seems many, many steps too far.
So, if you are out looking for a job, here are some tips to consider:
  1. Sanitise your account before you start applying for any jobs. Look for compromising messages, pictures, messages on walls, and remove or hide anything that you wouldn't want a prospective employer to see
  2. You can quote Facebook's legal terms, which clearly state that
    You will not share your password, let anyone else access your account, or do anything else that might jeopardize the security of your account.
    Explain that you are a law-abiding citizen, and you can in no way break this binding contract with Facebook.
  3. HackFactor author Neal Krawetz advises you to expose the company by anonymously posting online that they made this request during the interview. He also suggests that you consider suing them if you do not get the job.
  4. Tell them you don't use Facebook. Review your settings on your How You Connect page under Facebook's 'Privacy settings', you can tweak these, as shown below.
    This means that an employer won't find you during a search. Even friends of friends won't see you listed. The problem here of course is that you are lying, but my view is that human rights to privacy are a little more important than a white lie.
  5. Facebook setting


(864) 498-0569


Monday, January 9, 2012

Convicted murderer gets new trial after computer virus destroys data

Convicted murderer gets new trial after computer virus destroys data:

by Graham Cluley on January 4, 2012

It seems like the plot twist in a bad TV show - but it's true. A computer virus infection has helped a convicted killer get a new trial.



In July 2009, a Miami jury convicted Randy Chaviano, of Hialeah, Florida, of second degree murder.

Many might have thought it was the end of story when, after an eight day trial, Chaviano was given a life sentence for the shooting of Carlos Acosta.

But when the courts recently investigated whether Chaviano had grounds to appeal his conviction, it was discovered that no legal record of the trial could be found - giving the Third District Court of Appeal no choice but to throw out the conviction and grant Chaviano a new trial.

Stenographers at trials normally record proceedings on both paper and an internal disk. You've probably seen them busy at work, tapping wildly in the corner of the shot if you've ever seen a courtroom melodrama.

But Terlesa Cowart, the stenographer at Chaviano's 2009 trial, had not brought enough rolls of paper for her machine, forcing her to record details of the trial only on the device's internal disk. Subsequently, she transferred the data onto her PC, and erased it from the stenograph.



You can see where this is leading can't you?

An infection on Ms Cowart's PC by an unnamed virus is said to resulted in the loss of the legal records.

As a result, the trial has to be reheard, costing time and money, and witnesses and police officers will need to give evidence once again. And, of course, the relatives of the deceased man will have to go through the heartache of another trial.

It seems very sloppy to allow the only record of a trial's proceedings to be held on an individual's PC - it's like asking for trouble if it isn't at the very least held securely as a backup elsewhere.

It's claimed that stenographers in Florida have been resisting moves to replace them with digital recorders. Goofs like the one made by Terlesa Cowart are not going to do anything to help their argument.


Tuesday, November 15, 2011

Facebook users hit by hardcore porn, violence and animal abuse images

Facebook users hit by hardcore porn, violence and animal abuse images:


by Graham Cluley on November 15, 2011


Explicit and violent images have flooded the newsfeeds of many Facebook users in the last 24 hours or so.


The content, which includes explicit hardcore porn images, photoshopped photos of celebrities such as Justin Bieber in sexual situations, pictures of extreme violence and even a photograph of an abused dog, have been distributed via the site - seemingly without the knowledge of users.
Justin Bieber porn on Facebook
Some Facebook users vented their annoyance on Twitter, with some claiming they would deactivate their Facebook accounts as a result:
Tweets from upset Facebook users
One commenter to Naked Security, rxladyblue, told us:
I just viewed a gay pornography pic that was on the news feed under her name. She could not see the pic but all of her friends could see it.
Another Facebook user, ralahinn1, said:
One of my friend's accounts was compromised and messages containing a video were sent. My daughter's boyfriend had something posted on his wall that he couldn't see on his computer, but my daughter could see on his wall from hers.
StilettoIt isn't presently clear precisely how the offending content has been spread - whether users are falling for a clickjacking scheme, are being tagged in content without their knowledge, have poorly chosen privacy settings, have been tricked into installing malicious code, or have fallen victim to another vulnerability inside Facebook itself. What's clear, however, is that mischief-makers are upsetting many Facebook users and making the social networking site far from a family-friendly place.
Reporters at Gawker have speculated that hackers associated with Anonymous may be responsible for the attack, but that is unconfirmed.
So, it seems highly offensive spam content has successfully spread via Facebook for 24 hours or more. It's precisely this kind of problem which is likely to drive people away from the site. Facebook needs to get a handle on this problem quickly, and prevent it from happening on such a scale again.
Of course, this incident raises another important question. Many firms may be comfortable allowing users to access sites such as Facebook, but what happens when hardcore pornographic and offensive content is being spread. Should companies block access to sites hosting offensive content?
(864) 498-0569

Tuesday, November 8, 2011

IBM Simulates 4.5% of the Human Brain; Skynet Is Next

It’s pretty well known at this point that computers are quickly catching up with humanity as far as brain power is concerned. Storage-wise, we’ve been long surpassed by machines, and powerfully fast computers can run circles around the human brain in solving complex equations. On the other hand, humanity wins in the brain's sheer computational power and energy efficiency.
At least, for now.
IBM’s Blue Gene supercomputer has already surpassed the processing power of some of our weaker animal relatives; mice, rats and cats, and according to IBM’s research paper, the human brain isn’t that far ahead.
The brain contains on the order of 20 billion neurons that are connected by roughly 200 trillion synapses. IBM’s Blue Gene supercomputer has 147,456 parallel processors, each with about 1GB of working memory. This has enabled them to simulate about 4.5 percent of the human brain. That only leaves an estimated 732,544 processors left to add in to equal the processing power of 1 human brain--a task IBM says it will complete by 2019.
When was Judgement Day, again?
We’ve covered the apocalyptic aspect of Moore’s Law of computers before, but it’s worth revisiting here. Processing power on par with the human brain could spark real, thoughtful artificial intelligence and bring about the singularity of science fiction, a point where computers are smart enough to make themselves increasingly intelligent through iteration and design, outstripping humanity and becoming the most intelligent things around. Would this be beneficial to humanity or mean our end as the dominant species?
What do you think?
(864) 498-0569